Model & AI

The AI Act, per system and per obligation

The AI Act broken into requirements you can act on

Obligations differ by risk class and by the role you hold for a given system. Regulatory Nexus holds them as one requirement tree, each item traceable to the text it came from.

1
Requirements, not articles
One article holds several obligations. Each becomes its own work item.
2
Obligations follow the risk class
What applies depends on how the system is classified, so the classification is part of the mapping.
3
Provider or deployer
The same system carries different duties depending on the role you hold for it.
4
Read by the team that owns it
The same requirement, seen from data science, risk, legal or compliance.
Policy ABC
Partial matchAI-generated

Add an explicit obligation for deployers of emotion recognition and biometric categorisation systems to inform the affected natural persons about the operation of the system.

Reasoning
Reference

Your controls against the AI Act, with the reasoning

Risk & Control matches your existing model governance and data controls to the AI Act control objectives, classifies each objective covered, partially covered or not covered, and says why.

1
Reuse what you already have
Model risk, data governance and change management controls answer part of the Act. The mapping shows how much.
2
Gaps become work
Any objective short of covered goes to an owner with a deadline.
3
Drafted remediation
Missing or weak wording comes back as a drafted addition to approve, reject or reassign.
Recommendation AI
Addition: Add an explicit obligation that human oversight prevents risks to health, safety and fundamental rights from reasonably foreseeable misuse.

Obligations attach to systems, not departments

The Act is only workable once you know which systems you run, how each is classified and which role you hold. That inventory carries the mapping.
Systems and their classification
Each system is held with its risk class and the obligations that follow from it.
Documentation where it belongs
Technical documentation, instructions for use and logs tied to the requirement that asks for them.
Gaps per system
Findings are raised against the system and its owner, not against the framework in general.

Standards and guidance are still landing

Harmonised standards, guidelines and supervisory expectations continue to arrive. Horizon Scanning picks the change up and Impact Assessment scopes it to the systems and requirements you already mapped.

1
Change flagged at source
New AI Act standards, consultations and guidance are picked up as they publish.
2
Impact scoped to your mapping
The assessment names the systems, requirements and documents affected.
3
One audit trail
Every classification, override and approval stays traceable to the person who made it.
Recommendation AI
Addition: Add an explicit obligation that human oversight prevents risks to health, safety and fundamental rights from reasonably foreseeable misuse.

Next up

Each obligation attaches to the systems and controls that carry it in Regulatory Nexus.

Let us take you further

Schedule a 30 min call. No slide decks. Just a practical assessment of your needs and how we can help.